Internal reporting channels are mandatory across the EU

EU Whistleblower Protection Directive

Every private company with 50 or more employees operating in the EU must establish a confidential internal reporting channel, acknowledge reports within seven days, investigate and respond within three months, and protect reporters from all forms of retaliation. Non-compliance penalties reach up to €1M in some member states.

Next deadline:

The obligation is already in force. For companies with 250 or more employees in the EU, the compliance deadline was December 17, 2021. For those with 50 to 249 employees, it was December 17, 2023. Both deadlines have passed. The European Commission's July 2024 implementation report found widespread compliance gaps across member states. Organizations without a compliant internal reporting channel in place are currently in breach of national whistleblower protection law.

 

National implementing legislation differs in scope and enforcement approach: companies operating across multiple EU member states may face distinct obligations under each country's law, not just the Directive baseline. A group-level channel is not automatically sufficient for all jurisdictions.

Regulation timeline

16. December 2019

Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law enters into force.

2. July 2023

Germany’s Hinweisgeberschutzgesetz (HinSchG) enters into force, applying initially to organizations with 250 or more employees in Germany.

25. April 2024

Court of Justice of the EU issues its first late-transposition judgment, imposing sanctions on Poland (Case C-147/23).

6. March 2025

Court of Justice of the EU imposes financial penalties on five further member states for late transposition, Germany (fined €34 million), the Czech Republic, Hungary, Estonia, and Luxembourg.

17. December 2021

Member states’ transposition deadline. Private companies with 250 or more employees must have compliant internal reporting channels in place.

17. December 2023

Compliance deadline for private companies with 50 to 249 employees across all transposing member states. All in-scope companies are required to have a compliant reporting system in place.

3. July 2024

European Commission publishes its implementation report (COM(2024) 269), finding that all member states transposed the Directive’s main provisions but that key areas, material scope, conditions for protection, and protection against retaliation, still need improvement.

August 2025

European Commission opens a public consultation as part of its formal evaluation of the Directive, inviting assessment of its effectiveness and potential scope extensions.

1 / 8
  • 2019
    16. December 2019

    Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law enters into force.

  • 2021
    17. December 2021

    Member states’ transposition deadline. Private companies with 250 or more employees must have compliant internal reporting channels in place.

  • 2023
    2. July 2023

    Germany’s Hinweisgeberschutzgesetz (HinSchG) enters into force, applying initially to organizations with 250 or more employees in Germany.

  • 17. December 2023

    Compliance deadline for private companies with 50 to 249 employees across all transposing member states. All in-scope companies are required to have a compliant reporting system in place.

  • 2024
    25. April 2024

    Court of Justice of the EU issues its first late-transposition judgment, imposing sanctions on Poland (Case C-147/23).

  • 3. July 2024

    European Commission publishes its implementation report (COM(2024) 269), finding that all member states transposed the Directive’s main provisions but that key areas, material scope, conditions for protection, and protection against retaliation, still need improvement.

  • 2025
    6. March 2025

    Court of Justice of the EU imposes financial penalties on five further member states for late transposition, Germany (fined €34 million), the Czech Republic, Hungary, Estonia, and Luxembourg.

  • August 2025

    European Commission opens a public consultation as part of its formal evaluation of the Directive, inviting assessment of its effectiveness and potential scope extensions.

What the EU Whistleblower Protection Directive requires

The EU Whistleblower Protection Directive (Directive EU 2019/1937) entered into force on December 16, 2019, setting minimum standards across all EU member states for the protection of persons who report breaches of EU law. 

Private companies with 50 or more employees and all public sector entities, regardless of size, must establish a secure internal reporting channel, designate a responsible person to handle reports, acknowledge receipt within seven days, and provide substantive feedback on the outcome of the investigation within three months. Reporters must be protected from any form of retaliation, including dismissal, demotion, and blacklisting. 

Covered breaches span public procurement, financial services, anti-money laundering, consumer protection, environmental protection, food safety, transport safety, public health, and data privacy. Each member state has transposed the Directive into national law, with the option to set stricter requirements than the Directive baseline.

Common whistleblower compliance challenges

General-purpose tools cannot meet the Directive's technical channel requirements

Internal reporting channel requirements go beyond a shared email address or a general HR portal: a compliant channel must protect reporter identity, support written and oral reporting, accommodate anonymous submission where national law requires it, and provide a two-way communication mechanism. General-purpose communication tools typically lack the access controls and anonymity architecture these obligations require.

Every report carries its own seven-day and three-month deadline

The seven-day acknowledgement and three-month feedback obligations apply to every individual report, not as an average response rate. A single missed deadline creates a documented compliance failure, and manual tracking is unreliable when report volumes increase or cases span multiple jurisdictions.

Member states have transposed the Directive with significant variation in scope and timelines

Germany's Whistleblower Protection Act (HinSchG), France's Law on Improving the Protection of Whistleblowers (Loi Waserman), and Spain's Law 2/2023 on the Protection of Persons Who Report Breaches of Law each add requirements beyond the Directive baseline. For companies operating across multiple EU member states, compliance means meeting the specific requirements of each national law, not just the Directive minimum.

GDPR obligations apply to every whistleblower report alongside Directive requirements

Whistleblower reports contain sensitive personal data about the reporter and, typically, about one or more individuals named in the report. GDPR requires a documented legal basis for processing, strict access controls on reporter identities, and a defined data retention policy that shared mailboxes and general HR systems cannot satisfy.

Compliant reporting channels and case management for EU and national whistleblowing law

Secure channel setup, structured case management, automated deadline tracking, and audit-ready documentation run on one platform through the osapiens HUB for Complaint Management. Compliance data connects directly to CSDDD due diligence and CSRD reporting workflows without a separate data transfer.

Accept anonymous, pseudonymous, and identified reports through one configurable multi-channel intake

The osapiens HUB for Complaint Management accepts reports through a public reporting page, an AI-assisted chatbot, and email, available in more than 40 languages with voice recording and text-to-speech support for reporters who cannot read or write fluently. Anonymous reporters track case status through an encrypted complaint code that keeps their identity separate from the internal case ID, and the same channel covers complaint management obligations under CSDDD and LkSG.

Frequently asked questions

 

Establish a compliant internal reporting channel across every jurisdiction

The osapiens HUB for Complaint Management covers secure channel setup, structured case management, and automated deadline tracking for EU and national whistleblowing law. Trusted by 2,500+ companies worldwide to manage regulatory compliance obligations.

One HUB. Every compliance signal.